CVE-2026-25145 | chainguard-dev melange up to 0.40.2 Configuration File pkg/config/config.go LicensingInfos copyright[].license-path path traversal (GHSA-2w4f-9fgg-q2v9)
A vulnerability described as critical has been identified in chainguard-dev melange up to 0.40.2. This affects the function LicensingInfos of the file pkg/config/config.go of the component Configuration File Handler. Executing a manipulation of the argument copyright[].license-path can lead to path traversal.
This vulnerability is registered as CVE-2026-25145. The attack needs to be launched locally. No exploit is available.
Upgrading the affected component is recommended.